Table 3.
Percentage of changed predictions when using the FGSM perturbations for all Cifar-10 models and different values.
Model; | 1/255 | 2/255 | 4/255 | 8/255 | 16/255 |
---|---|---|---|---|---|
FP-net (N = 3) | 50.766 | 65.140 | 74.596 | 79.320 | 82.030 |
FP-net (basic) (N = 3) | 48.858 | 65.928 | 74.906 | 80.128 | 85.654 |
PyrBlockNet (N = 3) | 52.560 | 67.818 | 76.752 | 82.592 | 87.562 |
ResNet (N = 3) | 49.526 | 64.228 | 73.038 | 78.480 | 85.148 |
FP-net (N = 5) | 47.030 | 64.132 | 74.858 | 80.258 | 86.418 |
FP-net (basic) (N = 5) | 44.482 | 61.960 | 72.662 | 78.526 | 83.700 |
PyrBlockNet (N = 5) | 47.808 | 63.416 | 73.736 | 80.064 | 85.782 |
ResNet (N = 5) | 44.996 | 62.298 | 72.546 | 78.148 | 83.916 |
FP-net (N = 7) | 44.968 | 61.452 | 73.000 | 78.932 | 84.772 |
FP-net (basic) (N = 7) | 42.102 | 59.922 | 71.294 | 77.402 | 83.376 |
PyrBlockNet (N = 7) | 47.054 | 63.978 | 75.342 | 81.884 | 86.844 |
ResNet (N = 7) | 42.820 | 60.948 | 71.898 | 77.538 | 83.390 |
FP-net (N = 9) | 43.536 | 61.314 | 73.444 | 79.506 | 85.424 |
FP-net (basic) (N = 9) | 39.804 | 58.240 | 70.196 | 76.448 | 82.376 |
PyrBlockNet (N = 9) | 45.988 | 62.592 | 73.590 | 80.620 | 85.988 |
ResNet (N = 9) | 41.206 | 59.426 | 70.662 | 76.534 | 83.808 |